provider=near.
For a NEAR AI Cloud gateway flow, decide separately whether your policy requires provenance for:
- the configuration measured by
gateway_attestation - each NEAR model report in
model_attestations[], requested withprovider=near - both
Verification flow
- Verify the relevant Intel TDX quote first. For
model_attestations[], verify each candidate report separately before treating it as eligible evidence. - For each eligible NEAR model report, use the raw
info.tcb_info.app_composestring. Calculate its SHA-256 hash without parsing or reserializing it, and compare it with the configuration measurement in that report’s verified quote. - Extract every immutable image digest (
@sha256:…) from the matched configuration. - Cryptographically verify provenance for each required digest and confirm that the statement’s subject equals the image digest exactly.
- Apply your policy for repository, build identity, workflow, ref, and source revision.
Missing evidence
An unavailable provenance record, including an HTTP404, means the reported digest could not be verified under that policy. It does not by itself identify a security incident.
Fetch a fresh report after a deployment change. If the current evidence still lacks provenance required by your policy, treat that image as unverified.
When requesting help, share only non-sensitive verification metadata: the endpoint, UTC time, requested model, signing address,
info.instance_id when present, image name, and full digest. Never include API keys, prompts, or response content.